Courseiva

SAA-C03 Design Resilient Architectures Practice Question

A global application experiences frequent writes and must survive a full Regional outage with near-zero data loss. The product team also requires that users can continue to write during the incident using the closest Region. Which approach is most aligned with these requirements?

⚠ Common exam trap

It's easy for candidates to confuse 'multi-Region replication' with 'read replicas only' (Option D) or assume that periodic backups (Option B) provide sufficient durability, failing to recognize that near-zero data loss requires continuous asynchronous replication, not batch-based or on-demand replication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an active/active design with multi-Region data replication (for example, global tables for the write-heavy datastore) and route traffic to multiple Regions based on health and latency.

An active/active design with multi-Region data replication, such as Amazon DynamoDB global tables, allows writes to occur in any Region and replicates them to all other Regions with near-real-time latency (typically sub-second). This meets the requirement for near-zero data loss during a full Regional outage, as data is asynchronously replicated to multiple Regions, and users can continue writing to the closest healthy Region via Route 53 latency-based or geolocation routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use an active/active design with multi-Region data replication (for example, global tables for the write-heavy datastore) and route traffic to multiple Regions based on health and latency.

    Why this is correct

    Active/active with multi-Region replication (such as DynamoDB global tables) allows writes to succeed in multiple AWS Regions simultaneously, ensuring near-zero RPO and immediate write availability during a Regional failure. Routing traffic by health and latency distributes load intelligently and automatically shifts users to the nearest healthy Region, which directly satisfies the global, write-heavy workload's requirement for continuous writes with minimal data loss.

  • ✗

    Use warm standby with periodic backups of the primary write datastore every 24 hours.

    Why it's wrong here

    Warm standby with 24-hour backups of the primary write datastore offers recovery but with an RPO of up to 24 hours, because any writes after the last backup are lost. Moreover, restoring a backup and promoting the secondary to primary takes significant time (RTO), so the application would experience a lengthy outage without the ability to accept writes—contradicting the near-zero data loss and continuous write availability requirements.

    When this WOULD be correct

    This option would be correct for a non-critical application that can tolerate up to 24 hours of data loss and does not require write availability during a disaster. For example, a batch processing system where data is not time-sensitive and recovery time objective (RTO) is measured in hours.

  • ✗

    Use pilot light where the secondary Region runs only infrastructure templates and starts data replication only after detecting failure.

    Why it's wrong here

    Pilot light keeps the secondary Region dormant and only starts replicating data after a failure is detected, meaning the data store there is stale and cannot serve writes until replication is established. This creates an RPO equal to the time since the last replication and introduces failover latency, so it cannot provide near-zero data loss or permit continued writes during the incident—both of which are mandatory for the global write-heavy application.

    When this WOULD be correct

    A question requiring cost-effective disaster recovery with RPO of hours and RTO of minutes, where the primary region is expected to recover quickly and data loss of a few minutes is acceptable. For example: 'An application needs to recover from a regional failure within 30 minutes and can tolerate up to 1 hour of data loss.'

  • ✗

    Use a single-writer model in one Region and deploy read-only replicas in the other Region for continuity.

    Why it's wrong here

    A single-writer model in one Region with read-only replicas elsewhere cannot accept writes in the secondary Region during an outage; the application would either fail or need a manual/automated promotion of the replica to a writable state. That promotion is a failover mechanism with inherent RTO and potential data loss, whereas the stated requirement demands uninterrupted write capability and near-zero data loss during the incident, so this design does not meet the core need.

    When this WOULD be correct

    This option would be correct for a read-heavy application that requires strong consistency and can tolerate brief write interruptions during failover, with the primary goal of minimizing read latency in secondary Regions via read replicas.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Use an active/active design with multi-Region data replication (for example, global tables for the write-heavy datastore) and route traffic to multiple Regions based on health and latency.Correct answer▾

Why this is correct

Active/active with multi-Region replication (such as DynamoDB global tables) allows writes to succeed in multiple AWS Regions simultaneously, ensuring near-zero RPO and immediate write availability during a Regional failure. Routing traffic by health and latency distributes load intelligently and automatically shifts users to the nearest healthy Region, which directly satisfies the global, write-heavy workload's requirement for continuous writes with minimal data loss.

✗Use warm standby with periodic backups of the primary write datastore every 24 hours.Wrong answer — click to see why▾

Why this is wrong here

This option does not meet the requirement for near-zero data loss during a full Regional outage, as backups every 24 hours could lose up to a day's worth of writes. It also fails to allow users to continue writing during the incident.

★ When this WOULD be the correct answer

This option would be correct for a non-critical application that can tolerate up to 24 hours of data loss and does not require write availability during a disaster. For example, a batch processing system where data is not time-sensitive and recovery time objective (RTO) is measured in hours.

Why candidates choose this

Candidates may think periodic backups are sufficient for disaster recovery, underestimating the requirement for near-zero data loss and continuous write availability. They might also confuse backup frequency with replication.

✗Use pilot light where the secondary Region runs only infrastructure templates and starts data replication only after detecting failure.Wrong answer — click to see why▾

Why this is wrong here

Pilot light does not support near-zero data loss because data replication starts only after failure detection, leading to potential data loss during the gap. It also does not allow writes during the incident as the secondary region is not active.

★ When this WOULD be the correct answer

A question requiring cost-effective disaster recovery with RPO of hours and RTO of minutes, where the primary region is expected to recover quickly and data loss of a few minutes is acceptable. For example: 'An application needs to recover from a regional failure within 30 minutes and can tolerate up to 1 hour of data loss.'

Why candidates choose this

Candidates may confuse pilot light with active/active designs, thinking that infrastructure templates imply rapid failover, but they overlook the replication delay and lack of write capability during the incident.

✗Use a single-writer model in one Region and deploy read-only replicas in the other Region for continuity.Wrong answer — click to see why▾

Why this is wrong here

A single-writer model cannot survive a full Regional outage with near-zero data loss because writes are only accepted in the primary Region; if that Region fails, writes must stop until failover occurs, violating the requirement for continuous writes during the incident.

★ When this WOULD be the correct answer

This option would be correct for a read-heavy application that requires strong consistency and can tolerate brief write interruptions during failover, with the primary goal of minimizing read latency in secondary Regions via read replicas.

Why candidates choose this

Candidates may think read replicas provide write continuity, but they are read-only; the single-writer model seems simpler and familiar from traditional database setups, overlooking the need for multi-Region write capability.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.